Re: dkim signing outbound MAILER-DAEMON messages - is it worth it?

2022-05-09 Thread Matus UHLAR - fantomas
On 09/05/2022 12:48, Matt Kinni wrote: I have opendkim configured via 'smtpd_milters' to sign all outbound mail, and my domain publishes a "quarantine" dmarc record to enforce the consequences of this. I recently discovered that MAILER-DAEMON messages generated by postfix itself bypass this s

Re: dkim signing outbound MAILER-DAEMON messages - is it worth it?

2022-05-09 Thread Viktor Dukhovni
On Mon, May 09, 2022 at 03:03:42PM -0400, Wietse Venema wrote: > > - I don't quickly have an example of bad things that can happen > > with Milter inspection of Postfix-generated mail. That doesn't mean > > that such bad things don't exist. > > So, with that caveat you can turn on DKIMM signing o

Re: dnswl.org lookup error

2022-05-09 Thread Steffen Nurpmeso
Matus UHLAR - fantomas wrote in : |>Byung-Hee HWANG wrote in |> <87ee13qxa1.fsf@penguin>: |> ... |>|> First install a true local resolver such as bind9 or unbound and then |>|> switch your system to use it instead of systemd-resolved. To switch to |>|> bind9 you could try my |>|> https://ww

Re: dkim signing outbound MAILER-DAEMON messages - is it worth it?

2022-05-09 Thread Wietse Venema
Wietse Venema: > Matt Kinni: > > I have opendkim configured via 'smtpd_milters' to sign all outbound > > mail, and my domain publishes a "quarantine" dmarc record to enforce the > > consequences of this. > > > > I recently discovered that MAILER-DAEMON messages generated by postfix > > itself b

Re: dkim signing outbound MAILER-DAEMON messages - is it worth it?

2022-05-09 Thread Bernardo Reino
On 09/05/2022 12:48, Matt Kinni wrote: I have opendkim configured via 'smtpd_milters' to sign all outbound mail, and my domain publishes a "quarantine" dmarc record to enforce the consequences of this. I recently discovered that MAILER-DAEMON messages generated by postfix itself bypass this s

Re: "Alternating" IPv4 / IPv6 connections

2022-05-09 Thread Wietse Venema
Nikolaos Milas: > Hello, > > In our setup we have two mail gateway servers accepting incoming mail > (mailgw1.noa.gr [primary] and mailgw3.noa.gr), filtering mail (using > postscreen, amavis, spamassassin, clamav) and forwarding to the internal > mail server (vmail2.noa.gr) where user mailboxes

Re: "Alternating" IPv4 / IPv6 connections

2022-05-09 Thread Nikolaos Milas
On 9/5/2022 3:39 μ.μ., Nikolaos Milas wrote: As an example I am listing below some successive log entries (collated, usernames modified). For your reference, I am posting below the log entries (usernames modified consistently) of the same sessions (which I listed in my original message), as

Re: dnswl.org lookup error

2022-05-09 Thread Matus UHLAR - fantomas
Byung-Hee HWANG wrote in <87ee13qxa1.fsf@penguin>: ... |> First install a true local resolver such as bind9 or unbound and then |> switch your system to use it instead of systemd-resolved. To switch to |> bind9 you could try my |> https://www.timedicer.co.uk/programs/help/bind9-resolved-switch.sh.

Re: dnswl.org lookup error

2022-05-09 Thread Steffen Nurpmeso
Byung-Hee HWANG wrote in <87ee13qxa1.fsf@penguin>: ... |> First install a true local resolver such as bind9 or unbound and then |> switch your system to use it instead of systemd-resolved. To switch to |> bind9 you could try my |> https://www.timedicer.co.uk/programs/help/bind9-resolved-swit

Re: "Alternating" IPv4 / IPv6 connections

2022-05-09 Thread Nikolaos Milas
On 9/5/2022 3:39 μ.μ., Nikolaos Milas wrote: In our setup we have two mail gateway servers accepting incoming mail (mailgw1.noa.gr [primary] and mailgw3.noa.gr), filtering mail (using postscreen, amavis, spamassassin, clamav) and forwarding to the internal mail server (vmail2.noa.gr) where user

Re: dkim signing outbound MAILER-DAEMON messages - is it worth it?

2022-05-09 Thread Wietse Venema
Matt Kinni: > I have opendkim configured via 'smtpd_milters' to sign all outbound > mail, and my domain publishes a "quarantine" dmarc record to enforce the > consequences of this. > > I recently discovered that MAILER-DAEMON messages generated by postfix > itself bypass this setup and do /not/

"Alternating" IPv4 / IPv6 connections

2022-05-09 Thread Nikolaos Milas
Hello, In our setup we have two mail gateway servers accepting incoming mail (mailgw1.noa.gr [primary] and mailgw3.noa.gr), filtering mail (using postscreen, amavis, spamassassin, clamav) and forwarding to the internal mail server (vmail2.noa.gr) where user mailboxes lie. All servers are run

Re: dkim signing outbound MAILER-DAEMON messages - is it worth it?

2022-05-09 Thread Byung-Hee HWANG
Hellow Matt, Matt Kinni writes: > I have opendkim configured via 'smtpd_milters' to sign all outbound > mail, and my domain publishes a "quarantine" dmarc record to enforce > the consequences of this. > > I recently discovered that MAILER-DAEMON messages generated by postfix > itself bypass this

dkim signing outbound MAILER-DAEMON messages - is it worth it?

2022-05-09 Thread Matt Kinni
I have opendkim configured via 'smtpd_milters' to sign all outbound mail, and my domain publishes a "quarantine" dmarc record to enforce the consequences of this. I recently discovered that MAILER-DAEMON messages generated by postfix itself bypass this setup and do /not/ get signed, which unfo